CVE-2023-20569
published 2023-08-08CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution…
PriorityP426medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
6.16%
92.7th percentile
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
Affected
205 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 1st_gen_amd_epyc_processors | — | — |
| amd | 2nd_gen_amd_epyc_processors | — | — |
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
| amd | athlon_3000_series_mobile_processors_with_radeon_graphics | — | — |
| amd | athlon_3000_series_processors_with_radeon_graphics | — | — |
| amd | athlon_pro_3000_series_processors_with_radeon_vega_graphics | — | — |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7343_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7413_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7453_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7513_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7643_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-nvidia-6.2 vulnerabilities
osv·2023-10-31·CVSS 7.0
CVE-2022-45886 [HIGH] linux-nvidia-6.2 vulnerabilities
linux-nvidia-6.2 vulnerabilities
Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel
contained a race condition during device removal, leading to a use-after-
free vulnerability. A physically proximate attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-45886, CVE-2022-45919)
Hyunwoo Kim discovered that the Technotrend/Hauppauge USB DEC driver in the
Linux kernel did not properly handle device removal events. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2022-45887)
It was discovered that the NTFS file system implementation in the Linux
kernel did not properly validate MFT flags in certain situations. An
attacker could use this to construct a malicious NTFS im
OSV
linux-intel-iotg-5.15 vulnerabilities
osv·2023-10-24·CVSS 5.7
CVE-2023-1206 [MEDIUM] linux-intel-iotg-5.15 vulnerabilities
linux-intel-iotg-5.15 vulnerabilities
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplied data. A remote attacker could
use this to cause a denial of service (system
OSV
linux-raspi vulnerabilities
osv·2023-10-19·CVSS 5.7
CVE-2023-1206 [MEDIUM] linux-raspi vulnerabilities
linux-raspi vulnerabilities
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplied data. A remote attacker could
use this to cause a denial of service (system crash). (
OSV
linux-intel-iotg vulnerabilities
osv·2023-10-19·CVSS 5.7
CVE-2023-1206 [MEDIUM] linux-intel-iotg vulnerabilities
linux-intel-iotg vulnerabilities
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplied data. A remote attacker could
use this to cause a denial of service (system cras
OSV
linux-hwe-5.15, linux-oracle-5.15 vulnerabilities
osv·2023-10-06·CVSS 5.7
CVE-2023-1206 [MEDIUM] linux-hwe-5.15, linux-oracle-5.15 vulnerabilities
linux-hwe-5.15, linux-oracle-5.15 vulnerabilities
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniël Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplied data. A remote attacker could
use this to cause a denial of ser
OSV
linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-gcp, linux-gcp-6.2, linux-hwe-6.2, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-oracle, linux-
osv·2023-10-05·CVSS 7.0
[HIGH] linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-gcp, linux-gcp-6.2, linux-hwe-6.2, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-oracle, linux-
linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-gcp, linux-gcp-6.2, linux-hwe-6.2, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel
contained a race condition during device removal, leading to a use-after-
free vulnerability. A physically proximate attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-45886, CVE-2022-45919)
Hyunwoo Kim discovered that the Technotrend/Hauppauge USB DEC driver in the
Linux kernel did not properly handle device removal events. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2022-
OSV
linux-oem-6.1 vulnerabilities
osv·2023-10-04·CVSS 4.7
CVE-2023-20569 [MEDIUM] linux-oem-6.1 vulnerabilities
linux-oem-6.1 vulnerabilities
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem
discovered that the InfiniBand RDMA driver in the Linux kernel did not
properly check for zero-length STAG or MR registration. A remote attacker
could possibly use this to execute arbitrary code. (CVE-2023-25775)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a ou
OSV
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-ibm, linux-ibm-5.15,
osv·2023-10-04·CVSS 5.7
[MEDIUM] linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-ibm, linux-ibm-5.15,
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-ibm, linux-ibm-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle vulnerabilities
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expos
OSV
CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction
osv·2023-08-08·CVSS 4.7
CVE-2023-20569 [MEDIUM] CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
GHSA
GHSA-xr6c-7pfv-6vgf: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction
ghsa_unreviewed·2023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 GHSA-xr6c-7pfv-6vgf: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled?address, potentially leading to information disclosure.
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
Ubuntu
Linux kernel (NVIDIA) vulnerabilities
vendor_ubuntu·2023-10-31·CVSS 7.0
CVE-2023-3772 [HIGH] Linux kernel (NVIDIA) vulnerabilities
Title: Linux kernel (NVIDIA) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel
contained a race condition during device removal, leading to a use-after-
free vulnerability. A physically proximate attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-45886, CVE-2022-45919)
Hyunwoo Kim discovered that the Technotrend/Hauppauge USB DEC driver in the
Linux kernel did not properly handle device removal events. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2022-45887)
It was discovered that the NTFS file system implementation in the Linux
kernel did not properly validate MFT flags in c
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities
vendor_ubuntu·2023-10-24·CVSS 5.7
CVE-2023-38432 [MEDIUM] Linux kernel (Intel IoTG) vulnerabilities
Title: Linux kernel (Intel IoTG) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplie
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities
vendor_ubuntu·2023-10-19·CVSS 5.7
CVE-2023-4273 [MEDIUM] Linux kernel (Raspberry Pi) vulnerabilities
Title: Linux kernel (Raspberry Pi) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-suppl
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities
vendor_ubuntu·2023-10-19·CVSS 5.7
CVE-2023-38432 [MEDIUM] Linux kernel (Intel IoTG) vulnerabilities
Title: Linux kernel (Intel IoTG) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplie
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-10-06·CVSS 5.7
CVE-2023-4273 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniël Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplied data. A rem
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 7.0
CVE-2023-38427 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel
contained a race condition during device removal, leading to a use-after-
free vulnerability. A physically proximate attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.
(CVE-2022-45886, CVE-2022-45919)
Hyunwoo Kim discovered that the Technotrend/Hauppauge USB DEC driver in the
Linux kernel did not properly handle device removal events. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2022-45887)
It was discovered that the NTFS file system implementation in the Linux
kernel did not properly validate MFT flags in certain si
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2023-10-04·CVSS 4.7
CVE-2023-3773 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem
discovered that the InfiniBand RDMA driver in the Linux kernel did not
properly check for zero-length STAG or MR registration. A remote attacker
could possibly use this to execute arbitrary code. (CVE-2023-25775)
It was discovered that the USB subsystem in the Linux kernel contained a
race cond
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-10-04·CVSS 5.7
CVE-2023-4273 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Daniel Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory. (CVE-2023-20569)
It was discovered that the IPv6 RPL protocol implementation in the Linux
kernel did not properly handle user-supplied data. A rem
Ubuntu
AMD Microcode vulnerability
vendor_ubuntu·2023-08-30
CVE-2023-20569 AMD Microcode vulnerability
Title: AMD Microcode vulnerability
Summary: AMD processors may allow an attacker to expose sensitive information due to a
speculative execution vulnerability.
Daniël Trujillo, Johannes Wikner, and Kaveh Razavi discovered that some AMD
processors utilising speculative execution and branch prediction may allow
unauthorised memory reads via a speculative side-channel attack. A local
attacker could use this to expose sensitive information, including kernel
memory.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Microsoft
AMD: CVE-2023-20569 Return Address Predictor
vendor_msrc·2023-08-08·CVSS 4.7
CVE-2023-20569 [MEDIUM] CWE-1037 AMD: CVE-2023-20569 Return Address Predictor
AMD: CVE-2023-20569 Return Address Predictor
FAQ: Why is this AMD CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in certain processor models offered by AMD. The mitigation for this vulnerability requires a Windows update. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and provide protection against the vulnerability.
Please see the following for more information:
AMD-SB-7005
FAQ: Are any additional steps required to protect my system after installing the August Windows updates?
Customers who allow untrusted users to execute arbitrary code might wish to implement some extra security features within their systems. These features protect against the intra-process disclosure
Red Hat
amd: Return Address Predictor vulnerability leading to information disclosure
vendor_redhat·2023-08-08·CVSS 4.7
CVE-2023-20569 [MEDIUM] amd: Return Address Predictor vulnerability leading to information disclosure
amd: Return Address Predictor vulnerability leading to information disclosure
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
A side channel vulnerability was found in hw amd. Some AMD CPUs may allow an attacker to influence the return address prediction. This issue may result in speculative execution at an attacker-controlled instruction pointer register, potentially leading to information disclosure.
Mitigation: Mitigation, other than installed the updated packages, for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria compris
Debian
CVE-2023-20569: amd64-microcode - A side channel vulnerability on some of the AMD CPUs may allow an attacker to in...
vendor_debian·2023·CVSS 4.7
CVE-2023-20569 [MEDIUM] CVE-2023-20569: amd64-microcode - A side channel vulnerability on some of the AMD CPUs may allow an attacker to in...
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
Scope: local
bookworm: resolved (fixed in 3.20230719.1~deb12u1)
bullseye: resolved (fixed in 3.20230719.1~deb11u1)
forky: resolved (fixed in 3.20230719.1)
sid: resolved (fixed in 3.20230719.1)
trixie: resolved (fixed in 3.20230719.1)
No detection rules found.
No public exploits indexed.
Wiz
Crying Out Cloud - August Newsletter | Wiz
blogs_wiz·2023-08-30·CVSS 6.5
[MEDIUM] Crying Out Cloud - August Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's delve in.
Editor’s note: some of you may have noticed that we accidentally resent last month’s edition (July) – this was due to a technical issue for which we apologize.
Moving on – here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
## High severity vulnerabilities in Kubernetes on Windows nodes
Three high severity Kubernetes vulnerabilities were published on August 23. All three are flaws related to insufficient sanitization that could lead to privilege escalation. Kubernetes clusters are only affected by these vulnerabilities if they include Windows nodes. The vulnerabilities were assigned CVE-2023-3676
Tenable
Microsoft’s August 2023 Patch Tuesday Addresses 73 CVEs (CVE-2023-38180)
blogs_tenable·2023-08-08·CVSS 7.5
[HIGH] Microsoft’s August 2023 Patch Tuesday Addresses 73 CVEs (CVE-2023-38180)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2023-20569 amd: Return Address Predictor vulnerability leading to information disclosure
bugzilla·2023-05-16·CVSS 4.7
CVE-2023-20569 [MEDIUM] CVE-2023-20569 amd: Return Address Predictor vulnerability leading to information disclosure
CVE-2023-20569 amd: Return Address Predictor vulnerability leading to information disclosure
A side channel attack known as ‘Inception’ or ‘RAS Poisoning’ may allow an attacker to influence branch prediction, potentially leading to information disclosure.
Refer:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7005.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2230151]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2023:6595 https://access.redhat.com/errata/RHSA-2023:6595
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2023:7109 https://access.redhat.com/errata/RHSA-2023:7109
---
This issue has been addressed in the foll
http://www.openwall.com/lists/oss-security/2023/08/08/4http://xenbits.xen.org/xsa/advisory-434.htmlhttps://comsec.ethz.ch/research/microarch/inception/https://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/https://lists.fedoraproject.org/archives/list/[email protected]/message/L4E4TZNMLYL2KETY23IPA43QXFAVJ46V/https://lists.fedoraproject.org/archives/list/[email protected]/message/PKK3IA63LSKM4EC3TN4UM6DDEIOWEQIG/https://lists.fedoraproject.org/archives/list/[email protected]/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/https://security.netapp.com/advisory/ntap-20240605-0006/https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7005https://www.debian.org/security/2023/dsa-5475http://www.openwall.com/lists/oss-security/2023/08/08/4http://xenbits.xen.org/xsa/advisory-434.htmlhttps://comsec.ethz.ch/research/microarch/inception/https://lists.debian.org/debian-lts-announce/2023/08/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/https://lists.fedoraproject.org/archives/list/[email protected]/message/L4E4TZNMLYL2KETY23IPA43QXFAVJ46V/https://lists.fedoraproject.org/archives/list/[email protected]/message/PKK3IA63LSKM4EC3TN4UM6DDEIOWEQIG/https://lists.fedoraproject.org/archives/list/[email protected]/message/T7WO5JM74YJSYAE5RBV4DC6A4YLEKWLF/https://security.netapp.com/advisory/ntap-20240605-0006/https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7005https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7005.htmlhttps://www.debian.org/security/2023/dsa-5475
2023-08-08
Published